Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Tbox Ms Cpu32 Firmware MEDIUM 6.5
CVE-2023-36611

The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” pri…

Fix: after 1.50.598
Fix from $1,600 2023-07-03
Tauri CRITICAL 9.8
CVE-2023-34460

Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for…

Patch available
Fix from $2,300 2023-06-23
Remote MEDIUM 5.5
CVE-2023-0837

An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unpr…

Fix: 15.42.8+
Fix from $1,600 2023-06-14
Sharepoint Server MEDIUM 6.5
CVE-2023-33142

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Patch available
Fix from $1,600 2023-06-14
Windows Server 2012 HIGH 7.6
CVE-2023-32022

Windows Server Service Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-06-14
Vuforia Studio HIGH 8.1
CVE-2023-29152

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

Fix: 9.9+
Fix from $1,950 2023-06-07
Frontend File Manager Plugin MEDIUM 5.4
CVE-2021-4344

The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking m…

Fix: after 18.2
Fix from $1,600 2023-06-07
Product Input Fields For Woocommerce HIGH 7.5
CVE-2020-36696

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_d…

Fix: 1.2.7+
Fix from $1,950 2023-06-07
Foundry Comments MEDIUM 6.5
CVE-2023-30948

A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorizatio…

Fix: 2.249.0+
Fix from $1,600 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40521

Transient DOS due to improper authorization in Modem

No fix yet
Fix from $1,950 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40536

Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.

Mitigation only
Fix from $1,950 2023-06-06
Splunk HIGH 8.8
CVE-2023-32707EPSS 79%

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who hol…

Fix: 8.1.14 / 8.2.11+
Fix from $1,950 2023-06-01
Kyverno MEDIUM 6.5
CVE-2023-34091

Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field define…

Fix: 1.10.0+
Fix from $1,600 2023-06-01
Pomerium CRITICAL 9.8
CVE-2023-33189

Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. T…

Fix: 0.17.4 / 0.19.2+
Fix from $2,300 2023-05-30
Openemr HIGH 8.1
CVE-2023-2950

Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.

Fix: 7.0.1+
Fix from $1,950 2023-05-28
Go Pricing HIGH 7.5
CVE-2023-2496

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper cap…

Fix: after 3.3.19
Fix from $1,950 2023-05-24
Cyber Infrastructure MEDIUM 5.5
CVE-2023-2782

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build …

Fix: 5.3.1-38+
Fix from $1,600 2023-05-18
Agent HIGH 7.5
CVE-2022-45450

Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Wi…

Fix: 15+
Fix from $1,950 2023-05-18
Catalyst Center HIGH 8.8
CVE-2023-20182

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted …

Fix: 2.3.3.7 / 2.3.5.3+
Fix from $1,950 2023-05-18
Rocket.chat MEDIUM 6.5
CVE-2023-28325

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMes…

Fix: 6.0.0+
Fix from $1,600 2023-05-11
Endpoint Management Assistant MEDIUM 5.5
CVE-2022-45128

Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service vi…

Fix: 1.9.0.0+
Fix from $1,600 2023-05-10
Setup And Configuration Software MEDIUM 5.5
CVE-2022-43465

Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local ac…

Mitigation only
Fix from $1,600 2023-05-10
Endpoint Management Assistant Configuration Tool MEDIUM 5.5
CVE-2022-41610

Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated…

Fix: 1.0.4 / 2.4+
Fix from $1,600 2023-05-10
Rocket.chat MEDIUM 5.3
CVE-2023-28317

A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in a…

Mitigation only
Fix from $1,600 2023-05-09
Rocket.chat MEDIUM 5.3
CVE-2023-28318

A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus s…

Mitigation only
Fix from $1,600 2023-05-09
Visual Studio Code MEDIUM 6.6
CVE-2023-29338

Visual Studio Code Spoofing Vulnerability

Fix: 1.78.1+
Fix from $1,600 2023-05-09
Otrs HIGH 8.1
CVE-2023-2534

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and…

Fix: 8.0.32+
Fix from $1,950 2023-05-08
Samsung Core Services HIGH 8.6
CVE-2023-21505

Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.

Fix: 2.1.00.36+
Fix from $1,950 2023-05-04
Ms N5008 Uc Firmware CRITICAL 9.8
CVE-2023-30467

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to i…

Fix: 71.9.0.18-r2 / 73.9.0.18-r2+
Fix from $2,300 2023-04-28
Service Provider Management System CRITICAL 9.8
CVE-2023-2345

A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown…

Mitigation only
Fix from $2,300 2023-04-27